{"date_iso":"2026-08-01","date_human":"Saturday, August 1, 2026","generated_utc":"2026-08-01 13:34 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglJ30Q0_3tS3R4yrNdyR3sDdvBam1plVfmenBAFVPGmaVMErJ_oq_zXoIpeAjrFrkkFkudKUSHI-h82FGoiIJlkT2JghjQKrO2p7VmzpduPGv26gGgJ8I04b-U7eY1sihmIer0bGTtIof3CwH1vKmQOYLDvhNsYICoALOLhehhaLC65fPmAH_fpT0BrKk/s1600/hotel-wifi.jpg","description":"A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as","related":[{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages","link":"https://www.infosecurity-magazine.com/news/teams-phishing-abused-legit/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Russian spies take their half-click email attack from Zimbra to Outlook","link":"https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033","source":"The Register Security","date_rel":"30 Jul"}]},{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","Wired Security"],"coverage":6,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities","link":"https://cybersecuritynews.com/google-ai-fixes-chrome-vulnerabilities/","source":"Cyber Security News","date_rel":"23h ago"},{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"30 Jul"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits","link":"https://cybersecuritynews.com/arch-linux-disables-aur-package/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Arch-Linux-Disables-AUR-Package.webp","description":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks. Last month, a massive supply chain attack targeting the Arch User Repository (AUR) compromised more than 400 community-maintained packages , with attackers injecting\u2026","related":[{"title":"Arch Linux disables AUR package adoption to stop malware flood","link":"https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/","source":"Bleeping Computer","date_rel":"14h ago"},{"title":"BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations","link":"https://cybersecuritynews.com/blacktech-apt-deploys-blueshell-linux-backdoor/","source":"Cyber Security News","date_rel":"31 Jul"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Closed models refuse to help researcher swat Linux bug","link":"https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-linux-bug/5280647","source":"The Register Security","date_rel":"29 Jul"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"20h ago"},{"title":"Adobe security advisory (AV26-760)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-760","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"},{"title":"Adobe security advisory (AV26-756)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-756","source":"CCCS Alerts & Advisories","date_rel":"29 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CosmosEscape: Taking Over Every Database in Azure Cosmos DB","link":"https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db","source":"Wiz Research","date_rel":"30 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"20h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","source":"Wiz Research","date_rel":"29 Jul"}]},{"title":"Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely \u2013 Update Now","link":"https://cybersecuritynews.com/jetbrains-vulnerability-execute-malicious-code/","reason":"CVE-2026-63077","category":"News","sources":["Cyber Security News","Rapid7 Blog","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-63077"],"summary":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects\u2026","source":"Cyber Security News","date_rel":"22h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/Critical-JetBrains-Vulnerability-Allow-Attackers-to-Execute-Malicious-Code-Remotely-Update-Now-.webp","description":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access. According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating\u2026","related":[{"title":"Critical Code Execution Vulnerability Patched in TeamCity","link":"https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity","link":"https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity","source":"Rapid7 Blog","date_rel":"29 Jul"}]},{"title":"USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports","link":"https://www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports","reason":"Teams","category":"News","sources":["Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.","source":"Dark Reading","date_rel":"23h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt66a2e6a794ec3f06/6a6b70a2c08842d09cba7462/USA_Fencing-Jumio_Bala_Kumar.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Claude Mythos \u2014 Hype vs. Reality: What Security Teams Need to Know","link":"https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality","source":"Dark Reading","date_rel":"30 Jul"},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"30 Jul"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"29 Jul"}]},{"title":"North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials","link":"https://cybersecuritynews.com/north-korean-etherhiding-campaign/","reason":"Macos","category":"News","sources":["Cyber Security News","Palo Alto Unit 42","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine\u2026","source":"Cyber Security News","date_rel":"31 Jul","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/North-Korean-EtherHiding-Campaign-Targets-Crypto-Wallets-and-Developer-Credentials.webp","description":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine web search into a possible entry point for a serious compromise. The attack begins with a ClickFix-style lure that makes a browser page look like a frozen or rebooting Mac. Victims are told to open Terminal and paste a command that the malicious page has already copied to their clipboard, allowing the infection chain to start. AllSecure analysts identified the activity while\u2026","related":[{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"31 Jul"},{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","source":"The Hacker News","date_rel":"30 Jul"}]},{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"30 Jul","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"VMware fixes three critical flaws allowing auth bypass, VM escapes","link":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"29 Jul"}]}],"worth_reading":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Proofpoint Threat Insight"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"30 Jul","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://www.proofpoint.com/us/newsroom/news/max-severity-exchange-server-flaw-under-active-exploitation-kremlin-hackers","source":"Proofpoint Threat Insight","date_rel":"30 Jul"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-18452","vendor":"Rich Source","product":"DMS+ (Non-Mobile)","severity":"CRITICAL","score":10.0,"description":"DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18452"},{"id":"CVE-2026-17566","vendor":"pgadmin.org","product":"pgAdmin 4","severity":"CRITICAL","score":9.9,"description":"pgAdmin 4's Import/Export Data tool builds a psql \\copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17566"},{"id":"CVE-2026-52855","vendor":"pterodactyl","product":"wings","severity":"CRITICAL","score":9.9,"description":"Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{confi\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-52855"},{"id":"CVE-2026-14483","vendor":"WordPress","product":"Realtyna Organic IDX plugin + WPL Real Estate","severity":"CRITICAL","score":9.8,"description":"The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload fun\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0061,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14483"},{"id":"CVE-2026-14919","vendor":"WordPress","product":"ShopMonitor.io","severity":"CRITICAL","score":9.8,"description":"The ShopMonitor.io  WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0014,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14919"},{"id":"CVE-2026-17561","vendor":"HashiCorp","product":"Logsign SIEM","severity":"CRITICAL","score":9.8,"description":"Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.\n\nThis issue affects Logsign SIEM: before 6.4.108.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17561"},{"id":"CVE-2026-67822","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer witho\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67822"},{"id":"CVE-2026-68770","vendor":"Hugging Face","product":"sentence-transformers","severity":"CRITICAL","score":9.8,"description":"sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where t\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68770"},{"id":"CVE-2026-68771","vendor":"Comfy-Org","product":"ComfyUI","severity":"CRITICAL","score":9.8,"description":"ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializa\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68771"},{"id":"CVE-2026-17349","vendor":"pgadmin.org","product":"pgAdmin 4","severity":"CRITICAL","score":9.6,"description":"/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user\u2026","cwe":"CWE-522","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17349"}],"vendor_spikes":[{"vendor":"HashiCorp","count":48,"critical_count":1},{"vendor":"WordPress","count":43,"critical_count":3},{"vendor":"Unknown","count":20,"critical_count":1},{"vendor":"Red Hat","count":15,"critical_count":0},{"vendor":"pgadmin.org","count":6,"critical_count":3},{"vendor":"PHP Jabbers","count":5,"critical_count":0},{"vendor":"HCL Software","count":5,"critical_count":0},{"vendor":"thumbor","count":5,"critical_count":0},{"vendor":"ANDRITZ","count":4,"critical_count":0},{"vendor":"decidim","count":4,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":213,"has_news_data":true,"has_cve_data":true}